fix: validate admin settings file target (#894)

This commit is contained in:
Ngo Quoc Viet
2026-10-06 08:21:27 +09:00
committed by GitHub
parent 75be7cb3ea
commit 668f79c0ab
2 changed files with 12 additions and 5 deletions
+6 -1
View File
@@ -125,7 +125,12 @@ let writableCache: boolean | null = null
export function isSettingsWritable(): boolean {
if (writableCache !== null) return writableCache
try {
const dir = path.dirname(getSettingsPath())
const filePath = getSettingsPath()
if (fs.existsSync(filePath) && !fs.statSync(filePath).isFile()) {
writableCache = false
return writableCache
}
const dir = path.dirname(filePath)
fs.mkdirSync(dir, { recursive: true })
fs.accessSync(dir, fs.constants.W_OK)
writableCache = true
+6 -4
View File
@@ -154,9 +154,9 @@ describe("isSettingsWritable", () => {
expect(isSettingsWritable()).toBe(true)
})
it("returns false for an unwritable path", () => {
it("returns false when the settings path is a directory", () => {
_resetForTests()
process.env.SETTINGS_FILE = "/nonexistent-root-dir/settings.json"
process.env.SETTINGS_FILE = tmpDir
expect(isSettingsWritable()).toBe(false)
})
})
@@ -170,7 +170,9 @@ describe("settings file on disk", () => {
version: 1,
values: { TEST_ADMIN_VAR: "secret" },
})
const mode = fs.statSync(filePath).mode & 0o777
expect(mode).toBe(0o600)
if (process.platform !== "win32") {
const mode = fs.statSync(filePath).mode & 0o777
expect(mode).toBe(0o600)
}
})
})